Students taking a group photo.

Australia’s eSafety commissioner issued an advisory on July 28 urging schools to review how they share images online, citing a rise in the misuse of school photos. Between January and March 2026, the commissioner received over 100 reports concerning anonymous accounts targeting schools and school staff through misuse of images taken from official school websites and social media accounts. Much of the content, shared on platforms including TikTok and Instagram, involved artificial intelligence (AI)-generated materials depicting both children and school staff, including sexualized deepfake images, face swaps, and other manipulated imagery.
In 2024, Human Rights Watch documented that the personal photos of Australian children, including images posted by schools, had been scraped and used to train AI models. In addition to privacy risks, these practices enable the creation of convincing deepfakes, including sexualized imagery of children, which put children at even more risk of exploitation and harm.
Once online, images shared by schools can be rapidly manipulated and distributed. Photos in data sets used to train AI models can also reveal information that could identify children, including names, events, locations, and schedules. This could expose children to lasting harm, as both the original images and malicious deepfakes created from them can remain accessible indefinitely.
Australia has been considering stronger child data protections rules through the government’s proposed Children’s Online Privacy Code. The draft code, published in March, is expected to be finalized later this year. This code is a critical opportunity to strengthen protections for children’s personal information and require companies to act in children’s best interests in accordance with international human rights law. 

The cases highlighted by eSafety u

… [more]